Another Google redirect virus prob, All steps completed

Status
Not open for further replies.
I can boot into windows in normal mode only.

I tried to boot into recovery 3 times with no success.

I have also tried to boot into safe mode multiple times throughout this process but with no success.
 
Delete the version of ComboFix that you have and download a fresh one then run it and attach the log.
 
1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::

Folder::

Registry::

Driver::

FCopy::
c:\iastor.sys | C:\WINDOWS\system32\drivers\iaStor.sys

Save this as CFScript.txt, in the same location as ComboFix.exe


CFScriptB-4.gif


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
 
Update

I realized that I had MS Outlook and another program running during the last scan so I thought it would be wise to close all programs, restart and run COmbofix again.

This time it found a Rootkit running... it popped up a message and asked me to restart. I did so and it completed successfully.

Log shows some interesting developments - attached below

I WILL BE WAITING FOR A RESPONSE BEFORE PROCEEDING WITH THE ABOVE STEPS, PLEASE LET ME KNOW....
 

Attachments

  • Combofix log2 12-01-09.txt
    14.6 KB · Views: 6
Happy to report that the re-directs have stopped so far

Also I have not had any pop-ups

This goes for Firefox and IE

Again, I did not perform the last steps that you posted regarding Combofix


Please let me know what my next move should be... thanks again for your support
 
Argh...having an absolute 'mare.
Am in a similar situation - followed steps and still having no luck. Spybot, Avira, Malwarebytes, etc etc, It seems like I'm going around in circles as nothing is resolving the problems.

Redirecting from search engines is apparent from all browers (firefox, internet explorer and BT browser), and now also, each time a browser window is opened, multiple tabs open with errors and more than not crash the browser.
Am starting to get rather worried for security of internet banking and whatnot. So frustrating.

I hope my hijack this log gives some insight into the problems...

Thanks, any help would be INCREDIBLY useful as this is getting unbearable.

Again, in advance, thank you to anyone who could help...
 
Jonezy23,

Please follow the program here...

read the 4 stickied threads at the top of this forum

follow the procedures

then POST YOUR OWN THREAD



your best shot at fixing the problem is to follow the script and wait for an authorized user to assist you. good luck
 
added:


I have not had any redirects or pop-ups still since the last time I ran Combofix.


Looking forward to what I hope are going to be my finals steps towards a clean/healthy pc

thanks god!
 
Hi,

I think that were getting there.

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
c:\windows\system32\drivers\xnlqpgg.sys

Folder::

Registry::

Driver::
yafapid

Save this as CFScript.txt, in the same location as ComboFix.exe


CFScriptB-4.gif


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Also post a fresh HijackThis log for me.
 
Your logs are clean.

Follow these steps to uninstall Combofix and tools used in the removal of malware

Remove Combofix now that we're done with it.
  • Please press the Windows Key and R on your keyboard. This will bring up the Run... command.
  • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the "x" and "/")
    CF_Uninstall-1.jpg
  • Please follow the prompts to uninstall Combofix.
  • You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.
This will uninstall Combofix and anything assoicated with it.



  • Download OTC to your desktop and run it
  • Click Yes to beginning the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.
 
kritius,


It has been a real pleasure!

Although this process really tested my patience I am glad that I stuck with it and I am VERY thankful for your constant attention to my thread.


My perception on protecting my pc & its contents is quite different now and while this may sound funny I am glad that I caught this bug and as a result found this forum.



My immediate plan is to create a new user on my XP system that does not have administrative privileges for daily use.

Install Avira free antivirus, as well as a reputable firewall.


Do you have any additional suggestions for me?!?


Thanks in advance
 
Spyware blaster, and winpatrol are good.

Malwarebytes is an excellent app.

Was there anything in specific that you were looking recommendations on?
 
Status
Not open for further replies.
Back